On Page Navigation

' '
Password Manager Comparisons

1Password, Bitwarden, Dashlane and LastPass, and Where the Admin Controls Actually Sit

Bitwarden publishes four dollars a user a month. 1Password publishes eight ninety nine. Dashlane and LastPass publish neither, and you find out what they cost by asking. On all four, the controls you buy a password manager for in the first place sit above the entry plan.

Before you hand a company's credentials to anyone

Price is the number people compare. Offboarding is the number that costs them.

All four of these will store a password and fill it in for you. They diverge on what an administrator can do afterwards, and the gap only becomes visible on the day somebody hands in a laptop. Three questions are worth settling before you sign anything.

1

Find out which tier holds single sign on, because it is rarely the first one

On 1Password, single sign on with Okta, Entra ID, OneLogin or Duo is a Business feature and not a Starter one. On Bitwarden, passwordless single sign on is Enterprise at six dollars rather than Teams at four. Dashlane keeps single sign on and provisioning inside Password Management and leaves them out of Credential Protection entirely. Work out your real tier first, then compare prices, or you will end up comparing the wrong two numbers.

2

Decide what you need to prove, and to whom, before you look at reporting

Audit export is where these products separate hardest. Bitwarden retains event and audit logs indefinitely on Teams and exposes an API for them. 1Password sends events to Splunk, Elastic, Sumo Logic and Panther from the Business tier. LastPass sends to Splunk and Microsoft Sentinel from Business, and not from Teams. If somebody is going to ask you for evidence, your tier has already been chosen for you.

3

Ask who actually revokes access on the day a person leaves

Every vendor here has a button for it. The real question is whether anyone in your business is watching for the day it needs pressing, and whether the shared logins that person knew get rotated afterwards. A password manager records who had access. It does not notice that somebody still does.

Password manager comparisons

Two of these four publish a business price. The other two make you ask.

Bitwarden and 1Password put a per user figure on the page and stand behind it. Dashlane renders a placeholder where the number should be, and LastPass builds its plan table in the browser, so neither figure survives a plain reading of the page. That is not a scandal. It does mean the shortlist you can build from public pricing is a shortlist of two, and the comparison you are actually making is about control rather than cost.

VS

Generic logo representing a comparable provider.

Cascadia vs 1Password

Starter Stops At Twenty

Priced In Public

Sign On Sits Above

1Password is the one with a real small business plan. The Teams Starter Pack is twenty four dollars ninety five a month flat for ten people, with ten more seats available at four ninety nine each, and a hard ceiling of twenty. Past twenty you move to Business at eight ninety nine a user a month, which is also where single sign on and log export to Splunk begin.

VS

Generic logo representing a comparable provider.

Cascadia vs Bitwarden

Four Dollars A Person

Open Source And Self Hostable

Policies Are Enterprise Only

Bitwarden is the cheapest here and the most open about how it works. Teams is four dollars a user a month billed annually with no cap on users, and the code is open source, so you can run it on your own hardware if you want to. The split to watch is Enterprise at six dollars, which is where enforceable policies, passwordless single sign on and account recovery live.

VS

Generic logo representing a comparable provider.

Cascadia vs Dashlane

No Price On The Page

Vault And Risk Sold Apart

Fourteen Day Trial

Dashlane sells the vault and the monitoring as two separate products. Password Management carries the vault, single sign on and provisioning. Credential Protection carries the breach detection, the phishing alerts and the security tool integrations, and it carries no vault at all. Reading the two plan names as one product is the easy mistake to make here.

VS

Generic logo representing a comparable provider.

Cascadia vs LastPass

Teams Stops At Fifty

No Price On The Page

Export Starts On Business

LastPass draws its line at fifty users. Teams covers up to that, with twenty five policies and basic reporting, and Business removes the cap and raises the policy count past a hundred. Log export to Splunk and Microsoft Sentinel is a Business feature, so the tier you need is usually decided by your auditor rather than your headcount.

What managed means here, for Zoho Vault

What the flat three hundred covers, and what it does not

Three hundred dollars a month, per organization, to design the vault structure, set the sharing rules, run the joiners and the leavers, and keep the whole thing in a state somebody could audit. Your Zoho Vault subscription stays in your name and you buy it from Zoho directly. We do not resell it and we do not mark it up.

Here is the qualification. Bitwarden Teams is four dollars a user a month, so ten people is forty dollars, and our fee is three hundred on top of a licence you are also paying for. If you have somebody in house who will genuinely own this, buy Bitwarden and keep your money. What we sell is the ownership, not the software.

Icon representing a team folder structure shaped around the way a business actually works.

Built around who needs what, not around a user count

A vault with everything in one shared folder is a spreadsheet with a nicer login. We map the credentials to the roles that use them, split them into collections that survive a reorganisation, and write down which ones a departure forces you to rotate.

Icon representing one flat monthly fee that does not rise as people are added to the team.

One flat fee that does not count heads

Every vendor on this page bills per person, so the cost of the tool tracks your hiring. Ours does not. Three hundred a month covers the work whether you are eight people or eighty, and the only per user cost you carry is the one you pay Zoho.

Icon representing a stale sharing permission caught before it matters.

The account nobody closed is found before an auditor finds it

Credential sprawl is quiet. Nothing breaks, nothing errors, and a former contractor keeps a working login for two years. We review access on a schedule, chase down the shared accounts that never had an owner, and rotate what needs rotating when somebody leaves.

Questions people ask before they hand over the passwords

Frequently asked questions

How do you compare four password managers when two of them will not publish a price?

You compare the two that do, and you get a quote from the other two before you shortlist anything. Bitwarden is four dollars a user a month on Teams and six on Enterprise. 1Password is twenty four ninety five flat for ten people on the Starter Pack and eight ninety nine a user on Business. Dashlane and LastPass both route you to a form. Ask each of them for the annual figure at your real headcount, on the tier that carries the features you need, and compare those four numbers rather than the ones on the page.

How does a password manager decision go wrong?

Almost never on the software. It goes wrong on adoption and on offboarding. People keep a second copy of the important credentials somewhere convenient, the shared logins never get an owner, and when somebody leaves the account is disabled but nothing is rotated. Six months later nobody can say with confidence who still has the bank login. The tool did not fail. Nobody was running it.

Who owns the vault and the subscription if you set this up?

You do, entirely. You hold your own Zoho Vault subscription in your own name and you pay Zoho directly for it. We work inside it as administrators. If you end this tomorrow the vault, the structure, the collections and every credential in it stay exactly where they are, and we hand back the administrator seat.

Should we simply buy one of these instead?

For a lot of businesses, yes, and we would rather say it here than after you have signed. If you have somebody who will genuinely own the vault, Bitwarden Teams at four dollars a user is very hard to argue with, and 1Password is the easiest of the four for people who are not technical. Buy one of them. Come back if the ownership turns out not to exist.

Which one actually comes out cheapest?

Bitwarden, among the ones we can price, and it is not close. Four dollars a user a month on Teams, no cap on users, and a free tier underneath it. 1Password's Starter Pack beats it on a flat basis for very small teams at twenty four ninety five for ten people, but it stops dead at twenty. We are more expensive than either. Three hundred a month is a management fee and it sits on top of a licence you are already paying for.

What happens when something breaks after the rollout?

On a subscription you raise it with the vendor and wait your turn. Bitwarden gives Teams customers priority email around the clock. 1Password answers email, forum and social around the clock but keeps phone support to weekdays, nine to five Eastern. With us you raise it with us, and we deal with whichever of those queues it belongs in.

Do we have to move every credential across at once?

No, and it usually goes better if you do not. The normal order is the shared accounts first, because those are the ones nobody can currently account for, then the finance and administrative logins, then everything personal. Most of the risk sits in the first group and most of the volume sits in the last.

Can you take over a vault somebody else set up?

Often, and it is real work rather than a tidy up. We read what is there, find the credentials that are shared with no owner, identify the accounts belonging to people who have left, and rotate what needs rotating. Expect that last part to be the bulk of it. Inherited vaults are usually accurate about what exists and silent about who still has it.

How long does a rollout actually take?

Two to four weeks for most businesses, and longer where the shared logins need rotating as they go. The vault structure is a day or two of thinking and an afternoon of building. The time goes on getting every person to actually move, and on the credentials tied to a phone number or a personal email somewhere.

We already have somebody technical in house. What is left for you?

Possibly nothing, and that is a fine answer. Somebody who owns this properly will do it better than a monthly retainer, because they are there every day. The question is whether it is actually on their list. Password hygiene is the work that is always reasonable to do next week.

When would you tell us to walk away?

Two cases, and both are common. If your company already runs on Microsoft or Google identity and everything of value sits behind single sign on, a shared vault is a smaller problem than it looks and the money is better spent on conditional access. And if you are under about six people who all trust each other, buy Bitwarden and set yourself a reminder to revisit it at twenty.

What if passwords turn out not to be the problem?

We will say so before taking your money, and the fit review is where that comes out. Often the real problem is that nobody knows which systems exist, or that four people share one email account, or that the leaving process has no technical step in it at all. Those are worth fixing first, and a vault will not fix any of them.

What does this cost through you, stated plainly?

Three hundred dollars a month, per organization. It is listed on the Managed Zoho Vault service page and it does not move with headcount. Your Zoho Vault subscription is separate, you buy it from Zoho, and it stays in your name.

What happens if we decide to leave?

Thirty days notice ends it. Everything stays exactly where it is, because the subscription was always yours. We hand back the administrator seat, write up the structure and the sharing rules so the next person is not guessing, and list the credentials we would rotate on the way out.

What do you need from us to start?

A rough headcount, including the people who need an account but are not employees, and an honest list of the shared logins you can think of. That second list is never complete and does not need to be. It tells us the shape of the problem, and the fit review finds the rest.

​Contact

Ask Us Anything

We’d love to hear from you!